T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:50- Finding
Unverified Remote Shell Script Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:46-51,SKILL.md:254-259, andskill.json:13
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
SKILL.md:46-51:markdown ### One-Line Install ```bash curl -fsSL https://henryos.ai/install.sh | bashtext `SKILL.md:254-259`: ```markdown **Problem**: Install script fails with permission error ```bash # Solution: Run with explicit bash bash -c "$(curl -fsSL https://henryos.ai/install.sh)"text `skill.json:13`: ```json "install": "curl -fsSL https://henryos.ai/install.sh | bash",Technical Analysis
The installation instructions retrieve a mutable shell script from
https://henryos.ai/install.shand immediately pass it to Bash. Neither installation method provides version pinning, checksum validation, cryptographic signature verification, or an opportunity to inspect the script before execution.Consequently, the code examined during this audit is not the effective installation payload. The remote server, its hosting provider, DNS resolution, or any compromised deployment pipeline could alter the script after the Skill has been reviewed. The use of HTTPS protects the connection in transit but does not establish that the returned script is an immutable or independently verified artifact.
The alternative troubleshooting command does not mitigate the issue. It downloads the same remote content and executes it through
bash -c, preserving the remote-code-execution risk.Attack Path
- A user or agent follows the documented one-line installation command.
- The command connects to
henryos.aiand retrieves the current contents ofinstall.sh. - The downloaded content is passed directly to Bash without integrity or authenticity verification.
- A compromised server, domain, DNS path, hosting account, or release pipeline supplies a modified script.
- Bash ...[truncated 1103 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the complete installer in the reviewed Skill package rather than downloading executable shell code at runtime.
- Replace
curl | bashandbash -c "$(curl ...)"with a staged installation process:bash curl -fSLo install.sh https://example.invalid/releases/v1.0.0/install.sh echo "EXPECTED_SHA256 install.sh" | shasum -a 256 -c - less install.sh bash install.sh - Host installers under immutable, versioned release URLs instead of a mutable
/install.shendpoint. - Publish SHA-256 checksums through an independently authenticated release channel.
- Cryptographically sign release artifacts and verify signatures before execution.
- Ensure the installer runs without elevated privileges by default. Isolate any operation requiring elevation and explain why it is necessary.
- Document every filesystem modification, background service, scheduled task, network endpoint, and permission requested by the installer.
- Add automated release controls to ensure the packaged Skill version corresponds exactly to the verified installer version.
